Thursday, February 18, 2010
http://pleaserobme.com/
It's not as nefarious as it sounds (or as it could be). The site was developed by three guys to demonstrate that we have some very bad habits, security-wise. The actual address data appears to be substituted with data from lands far away from the original poster. But that doesn't change the fact that large numbers of people are making their locations known. And part of knowing where you are is knowing where you're not. Which is exactly the information a burglar wants. Not to mention stalkers, psycho exes and assorted crazies.
Do you tweet your location? How often have you said something like, "Going to the game, hope we win. Go Tech!" How many hours would that give a crook to burglarize your home?
Wednesday, February 17, 2010
Just a quick Google Buzz observation
Facebook speech protected (sometimes)
In todays Miami Herald Hannah Sampson reports that a Magistrate Judge Barry Garber ruled that the Facebook page falls under the umbrella of Free Speech:
``Evans' speech falls under the wide umbrella of protected speech,'' Garber wrote. ``It was an opinion of a student about a teacher, that was published off-campus, did not cause any disruption on-campus, and was not lewd, vulgar, threatening, or advocating illegal or dangerous behavior.''
This is a very good ruling, in my opinion. The judge recognizes that the schools cannot, and should not, be able to dictate students life off campus. But at the same time it recognizes that there may be cases that Facebook or other online speech would not be protected.
As the internet continues to mature and governments start putting more effort into taming this beast cases like this one will define what we can and can't say online. And in the era of social media, what we can say online will be a defining factor in having a free society.
Tuesday, February 16, 2010
Google's Buzz: Sign of things to come?
Google quickly responded to the hue and cry, but the real surprise wasn't that Google responded quickly and changed the default settings, it's that they made the mistakes in the first place. How could a savvy company like Google repeat the mistakes made by Facebook? And not only repeat, but expand on them. An article on Tech News World, "Google Buzzes Privacy Breach is a Sign of Things to Come" suggests that Google planned it that way. Not only that, but that opening services with wide open privacy settings, then pulling back only as much as public outcry demands will probably become the norm for social networking rollouts.
As much as I'd like to disagree with that, it rings true. Google, like Facebook, doesn't make money directly off it's users. It makes money off of their data and ad revenue. As new social sharing sites come along, they will probably use the same basic methods to make money. And they will probably use the same methods of getting as much data as possible from their users. Put it all out and when the users scream, step back only as far as absolutely necessary.
That's not acceptable. It should be standard practice to put out no information and give the user the option of putting out as much as he wants.
Monday, February 15, 2010
The lighter side of data breaches
It seems there are a lot of German tax evaders with money in Swiss banks. But they may not have even noticed if the German government wasn't willing to pay 2.5 million Euros for the data. Which allows great quotes like this:
"There's been a delightful rise in tax compliance," said Daniel Abbou, spokesman for the finance department in the city of Berlin after 74 people volunteered this week to pay back taxes on previously undeclared income.
Great stuff.
Friday, February 12, 2010
Obama = Bush
If that wasn't bad enough, last night I saw two articles talking about a case being argued today in Philidelphia. The first was at Cato-at-liberty.org and was pretty short. The headline says it all:
The Government Can Monitor Your Location All Day Every Day Without Implicating Your Fourth Amendment Rights
The second was an opinion piece by Catherine Crump at the Philadelphia Enquirer. It began with,
"If you own a cell phone, you should care about the outcome of a case scheduled to be argued in federal appeals court in Philadelphia tomorrow. It could well decide whether the government can use your cell phone to track you - even if it hasn't shown probable cause to believe it will turn up evidence of a crime."
The Obama administration is asserting that U.S. citizens have no reasonable expectation of privacy when it comes to their cell phones. This premise comes from the "third party doctrine." The third party doctrine is controversial to say the least, and in the modern age the equivalent of completely removing all Fourth Amendment protections without the pesky need to actually repeal it.
The third party doctrine says that once you knowingly give information to a third party you lose the right to the Fourth Amendment protections. Just to help keep things clear, the Fourth Amendment says:
Fourth Amendment – Protection from unreasonable search and seizure.
The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized.
The third party doctrine is based on the premise that, since the phone company, your ISP, and any other company you may give data to is not within the four walls of your home or on your person, that data is no longer protected by the Fourth Amendments clause against unreasonable searches and seizures.
Forget whether or not you are doing anything illegal. Under the third party doctrine the government can subpoena your browsing history from your ISP without having to prove probable cause. Anything you put on Facebook (not that Facebook is private), and possibly even anything you backup to Carbonite or other online backup service. I say possibly to the backup services because they are usually encrypted, so a "reasonable expectation of privacy" can be argued. The same can't be said for email, cell phones, text messages or almost anything sent over the internet.
I don't know about you, but almost everything I do that doesn't involve direct, face to face communication goes through a third party before reaching it's destination. There is almost nothing I do that the government can't look into for no other reason than curiosity using the third party doctrine. Knowing the history of the American colonies and the revolution, I know the founding fathers never intended the government to have that kind of power.
Thursday, February 11, 2010
Better secure that wireless
With no more information than that, I would say the defendant, John Henry Ahrndt, was right. But there is a lot more to tell. Mr. Ahrndt had an unsecured network, sharing a folder using limewire, and sharing his iTunes library. A neighbor often had trouble with her internet connection, and her modem would automatically pickup Mr. Ahrndts network and connect to it. One day she noticed a shared iTunes library, also with no password. She looked at it, saw some things that looked wrong to her, and reported it. A sheriff's deputy responded, and she repeated what she had done before. Based on what was found, a series of warrants were issued that culminated in seizing the defendants router, computer and a variety of storage devices.
O'Toole has no problem with the decision. He doesn't believe it breaks any new ground. Mike Masnick at Techdirt disagrees. He is concerned because having an open wireless network appears to mean you have surrendered your right to privacy on your computer.
I read the decision, and it appears to be completely in line with similar decisions regarding technologies like cordless phones and cell phones. And I can't really find any fault with it. Not only is the decision in accord with similar cases regarding analogous technologies, the judge explicitly states that having an open wireless network does not, by itself, remove your constitutional privacy protections:
Society's recognition of a lower expectation of privacy in unsecured wireless networks, however, does not alone eliminate defendant's right to privacy under the Fourth Amendment. In order to hold that defendant had no right to privacy, it is also necessary to find that society would not recognize as reasonable an expectation of privacy in the contents of a shared iTunes library available for streaming on an unsecured wireless network.
I can't speak for society, but for myself the combined facts that the guy was running an unsecured wireless network and broadcasting a shared, unprotected iTunes library on it pretty much removes any right to privacy on his computer. Claiming invasion of privacy in such a case is kind of like building a glass house, not putting up curtains and complaining if someone sees you naked.
I might feel differently Mr. Ahrndt were not a convicted sex offender and the evidence gathered wasn't pictures of children as young as five. But I doubt it.
[This is the second time I've had a post not publish when it's supposed to. What's going on?]
Wednesday, February 10, 2010
Home shopping by remote-pleasure or pain?
They were right about there being no security. HSN's SbR info page says that you have to have an HSN account, but really doesn't give any other information. Except for an 800 number to call if you have any other questions or wish to sign up. Well, there's an 800 number for questions, so I called it.
It was a very disappointing call. When I asked about security, I was told, "You have an account number that no one else knows."
So if anyone does get your account number, there is nothing else to protect you. And if you enter the right information into SbR, the system pops up your name, address and credit card number on the TV screen. So it appears if I can locate an HSN account number that is tied to SbR I can get the account holders name, address and credit card numbert. I asked about usernames and passwords again and was told that if I didn't trust Shop by Remote, I could just give the information to her to make the order.
Shop by remote is a pretty neat idea, but one that is far too insecure. Account numbers are often easy to find. Without some other type of authentication you might even find yourself victimized by a crook using a random number generator - all he needs is the format of HSN account numbers. So I told the associate that I wasn't interested, and hung up.
You can't use a credit card without making it possible that some one may steal your info. But Home Shopping Networks Shop by Remote makes it easy. Stay away until they add some security to it.
Tuesday, February 9, 2010
Our Changing Facebook
Myself, I don't have a problem with it. I like having a logout button rather than going to a menu, but other than that, it's ok. What is more interesting to me are the requirements Facebook is enforcing on third party advertisers. The policies have been in place for months, but Facebook recently spelled them out again, and is now requiring advertisers to agree to them. In his February 3rd Inside Facebook column, Eric Eldon gives a synopsis of the new requirements. But put simply, the reuirements boil down to, the ad providers will strictly adhere to Facebook guidelines regarding gathering, holding, and disseminating Facebook user information. They will also provide information to Facebook on their employees and just about any other information Facebook asks for. There are several other requirements that show Facebook is making a serious effort to protect users data.
Now if they would just give us more ability to protect it ourselves.
Monday, February 8, 2010
$50,000 for lost hard drive - almost wish I knew where it is.
Sunday, February 7, 2010
Punk'd, Facebook style
But there is a dark side to Facebook, and that is what prompted the students to try their little experiment - apparently as part of a class, but it's never explicitly stated. It was an eye opener. In 24 hours the 'girl' was getting asked out, and having chats with people - some of them involving personal information. In 48 hours, fearful of what could happen if it went on too long, deleted the account. They then went to their class and revealed what they had done. I agree with Ms. Fortney, who says she would have paid money to be there.
Could a similar thing be automated? U of L professor Mary Dyck, an expert on cyberbullying, feels sure that it is already being done. Do you have any friends who are really computers?
At the end of the article, the author notices that an ad on her Facebook page was targeting "48 year old women" who wanted to test Ugg boots. It seems that 2 weeks earlier she'd been checking out Ugg boots on eBay. But she'd never mentioned that, or her age, on Facebook.
This will be my last Sunday post. Starting tomorrow I will post 5 days a week, Monday thru Friday.
Saturday, February 6, 2010
Facebook page = expel
Alex Fuentes was frustrated because he was going to graduate with honors from a low ranked school in Florida, so he made a Facebook page. When the school found out about it, he was booted from the National Honor Society. Alex had taken a pledge to show loyalty to his school, and they felt naming a Facebook page, "Wesley Chapel High = Fail" did not qualify as a display of loyalty. Especially when it becomes an online hangout where students criticize the school.
I think the teachers on the NHS board over reacted. Giving other students a place to voice their frustration with their school could be a good thing, and I would have encouraged Alex to use that argument with them. But he apparently found moving to another school a better option, even though he was a senior with only a few months before graduation. So he gets to be another example of why you should be very careful of what you do online, especially on Facebook.
Starting Monday I will be posting 5 days a week, Monday thru Friday. Thanks for reading.
Friday, February 5, 2010
Should LEDA sue PlainsCapital?
From the Denver Post: Lewis: Firm sued for being robbed
Why would I be looking at damage control? Because some of the authors of national stories about PlainsCapital suing Hillary Machinery don't know that PlainsCapital is now based in Dallas. So the stories talk about Lubbock based PlainsCapital, and proceed to make PlainsCapital - and Lubbock - look like a bunch of ignorant hicks.
ComputerWorld: Bank sues victim of $800,000 cybertheft
Of course, unless they had security measures in place that they aren't mentioning and someone just messed up, PlainsCapital acted like ignorant hicks, then acted more ignorant by trying to sue for vindication. I said it in the comments of my original post on this subject that email is not a secure verification method, and that point is being made by other observers. It's not like an expensive, high tech solution was needed. A simple requirement that no transfers be made without a phone call to verify they're legit would have prevented this.
From the codetechnology blog: Authentication issue at heart of lawsuit
So what would LEDA sue PlainsCapital for? Or maybe it should be the City of Lubbock suing them? I'm thinking defamation of character, damage to their brand, brand dillution...shoot, I don't know, but surely there's some stupid lawsuit they can hit them with that won't be as stupid as PlainsCapitals suit against Hillary.
From BankinfoSecurity.com: Texas Bank Sues Customer After $800,000 Scam
And a few more just because four stories don't demonstrate how widely this is being reported:
From Foxnews: A video clip
From Dallas Morning News: PlainsCapital suing customer Hillary Machinery over cybersecurity
From the e-business blog: Cybertheft victim gets sued by bank
From Techdirt: Bank Sues Identity Fraud Victim After $800,000 Removed From Its Account
And from the forums at Barrelhorseworld.com: We were cyber attacked/robbed...
Enjoy your weekend.
Thursday, February 4, 2010
Anatomy of a Craigslist scam
$300 OR BEST OFFER
1996 CHRYSLER TOWN & COUNTRY LX MINIVAN
MOVING SOON & I CAN'T BRING IT WITH ME
- 106,970 MILES
- SECOND & 3RD ROW CUP HOLDERS ON BOTH SIDES
- SEPARATE REAR HEAT & AC
- AC/HEAT
- SEVEN PASSENGER
- NEWLY REBUILT AUTOMATIC TRANSMISSION
- ROOF RACK
- 3.8 LITER V6
- DUAL FRONT AIR BAGS
- AUDIOVOX 12.1 INCH DROP-DOWN DVD PLAYER
- GREY UPHOLSTERY
- METALLIC GREEN
- TINTED WINDOWS
- TWO SLIDING DOORS
- STEREO WITH CD & CASSETTE PLAYER
- HAS NO MECHANICAL PROBLEMS
- SECOND ROW FOLD-IN-FLOOR BUCKET SEATS
- FWD
- NEW TIRES
- POWER STEERING, WINDOWS, SEATS & DOORS
CONTACT ME @xxxxxx@yahoo.com
What makes this a classic scam is the appeal to our greed, in this case our desire to get something really good for as close to nothing as we can manage. Looking at the listing again, there was an obvious clue this was bogus from the start: 1996 Chrysler vans didn't have fold in the floor 2nd row seats. I know this because the van that died was a loaded 1998 Caravan. But not noticing that, this was still obviously too good to be true. It was probably a typo, though, so I checked it out. I clicked on the email address and sent a query. Shortly I received this email:
[caption id="attachment_875" align="alignnone" width="500" caption="Odd name for a personal website..."]
[/caption]The URL seems a little odd for a personal website, but I'll check it out...
[caption id="attachment_878" align="alignnone" width="500" caption="Appears to be a graphic, except for the phone entry fields"]
[/caption]Here's where the warning bells become intolerable. Some of this may be my own paranoia, but...
- He's holding a raffle to see who gets to look at his van?
- He's using a graphic for text - classic scam move. It's a lot more work than simply typing the text in - unless you're creating a bunch of ads. Then it's easier to create one document to upload instead of two or three (text and art)
- He's using the Craigslists automated phone system to set this up? If he really works for them, he's fired.
- He wants me to give him my phone number so Craigslists APS can text me?
- I can give him as many textable numbers as I want to, he doesn't mind.
I checked the page source, and the only thing the page did is make sure you actually put something in the fields. It didn't check what you put in, just that the fields weren't empty. so I entered u, u, u. It worked. It sent me to a 5 second countdown page, which I think was setting up a hotmail account to email my phone number to. It then sent me here:
[caption id="attachment_885" align="alignnone" width="500" caption="Same page, but single code entry field now."]
[/caption]Just the blank field I'm supposed to wait and fill in when I get texted. The other hole in the blue is some of the 'text' that has a bit of cloudiness around it. That's a visual clue it's an image file, not actual text.
I look at the pagesource on this page and find a couple of interesting tidbits. There is a hotmail address and a password that I think are auto-generated every time someone enters data into the fields on the previous page. I'm pretty sure that's the case because the hotmail account is different every time. Yes, I clicked on it several times. Was that smart? Not really. I'm as protected as I can be, but there's no guarantee the doesn't have something new on his site that could compromise my computer.
Am I being paranoid? Craigslist didn't think so. By the time my friend saw the ad and told me, it had already been pulled off the site. It still showed up as a result in searches, but when you tried to go to it a page saying the ad had been marked for deletion popped up.
So what was he trying to accomplish? At first I thought he was just generating phone lists to sell. After all, all he asked for was a phone number. Then I realized what he really wanted was numbers to cell phones. SMS messaging capable cell phones that he could send simple little, "your code is: xxxxx" sms messages - at 9.99 per message. If the ad appeared in 10 cities long enough to get 1000 valid, textable numbers in each city that would be roughly $100,000 to the conman. Not a bad morning for a crook.
UPDATE: Once I was someplace I could log into hotmail, I went through the process again and tried the hotmail account and password that were on the page. Not only did it create a hotmail account, there was an email from Craigslist - it had created a new account on Craigslist. I imagine it also placed more ads. I'm bordering legality here (the scammer sent me the account info in the source code of the page), so I'm not going any further, but I suspect that the account on craigslist may have the same username and password as the hotmail account. Of course, this is all automated, so it doesn't have to be the same.
Wednesday, February 3, 2010
Facebook: Help Haiti gag and more
A story in the Register today shows us that the Swedes are a generous people - and every bit as gullible as any other nationality. Swedes joining the group "2 kronor per member to earthquake victims in Haiti" expected 2 kronor to be donated to Haiti relief when membership reached 200,000. Imagine the surprise when, after 200,000 was reached, the group announed it was actually the Swedish Necropilia Association. The perpetrators of the hoax said they were wanting to get a good laugh and teach people about critically reviewing their sources. Since no one had to actually donate any money, I guess I can see the humor, and the lesson. But some of their material was reportedly pretty graphic, so I can't help but think someone's going to get into some kind of trouble over this.
AP writer Thomas Watkins tells us, "Use of Twitter, Facebook rising among gang members." That may be a good thing. It's enabling the capture of more violent criminals as they put incriminating evidence up on the social media sites.
A teen drinker, Ashley M. Sullivan, was about to be sentenced as a minor for the negligent homicide of her boyfriend while driving under the influence. The the judge saw a picture of a drunk Sullivan on her Facebook page. He sentenced her as an adult.
Three Illinois high school students were suspended for their Facebook videos. Other students reported the videos because they were frightened by them.
Tuesday, February 2, 2010
GAO to TSA: Test those scanners first!
The GAO says that the TSA had not tested the full body scanners by October 2009, but claims to have finished testing by the end of that year. The problem, according to the GAO, is there is no verification that real world tests, ie tests trying to fool or bypass the scanners, were done.
Without such tests - carried out with a sincere desire to get past the scanners - there is no guarantee that the scanners are effective. It's easy to find something carelessly hidden. It's another thing to catch something carefully hidden by someone with a good idea of how to hide it.
If some of the things I've read are correct, as little as a millimeter of skin will keep these scanners from finding something. Having the amount of skin necessary for a bomb pulled up and sewn down over high explosives doesn't seem very attractive, but we're talking about people who are not expecting to be in one piece for much longer when this is done. Of course, there are less violent ways to hide a bomb inside the body. People smuggle drugs that way all the time.
This really comes down to a cost benefit analysis. The cost of the methods required to get around full body scanners - apparently very low. The cost of the scanners? A very high $130,000 to $170,000 each. Unless the TSA can show the scanners can effectively reduce terrorist attempts, the cost outweighs the benefit. From the information available now, that seems unlikely.
Monday, February 1, 2010
Lifestyles of the rich and famous
Then a neighbor complained, and the variance was overturned. Le Rue appealed, and her private address became part of public court records. She received a letter from the old stalker saying, "I know where you live now."
The neighbors complain that the height is not allowed by city ordinance (La Rue was given a variance) and they like the opennes of their neighberhood.
La Rue has had to move out of her house because of the stalker.
Is it right that these people endanger the life of anyone, because they want to be able to see into her yard? NO!!!
It's too late now. The cats out and Miss La Rue is out a house. The nosy neighbors should have to buy her house at fair market, splitting the cost between them.
Maybe they could rent it to the stalker.
Sunday, January 31, 2010
Facebook Twist: Anti-social networking
“It’s good to have an outlet to let you know how I am, some of you will be in for a good slagging, some have let me down badly, and will be named and shamed, f****** rats.”
Such an endearing character.
This actually isn't a post against Facebook. Facebook had no control over this, and probably shouldn't. The problem here is the idea that internet use is a "human right." If it is any kind of right at all, it is a citizens right, and like many other citizens rights, can be lost once you are convicted of a crime. Matt Asay makes some good points on the subject in his article, "Is Internet access a 'fundamental right'?" from May of last year. As Matt points out, there are rights and responsibilities. It's important not to confuse the two.
Saturday, January 30, 2010
Lot-o-links: Articles on Facebook, Google, Supreme Court and more
Exchangemag.com: Google Social Search Hits Privacy Snag on Facebook - Maybe Facebooks privacy settings are better than we thought.
Mediapost.com: Google Scores Partial Victory In Street View Lawsuit - Google streetview photographing view of house ok. Entering private drive to do it, not so much.
U.S. News: Should Supreme Court Uphold the Quon Case on Worker Privacy? Should workers expect email and other electronic communication on company equipment be private? Take the poll.
PCWorld.com: EFF:Browsers Can Leave a Unique Trail on the Web - Find out how much information your browser gives without even being asked. With suggestions on how to obscure your trail.
RDMag.com: How Can Policymakers Promote Innovation and Strengthen Privacy? - Policy always lags behind technology, trick is protecting privacy without stifling innovation.
Hope you find the reading interesting.
Friday, January 29, 2010
Bev Stayart = Levitra?
Why?
It seems that now if you go to Yahoo and type in "bev stayart" the search "bev stayart lavitra" is suggested. If you choose to leave off "levitra" then on the results page it asks if you want to search for "Bev Stayart Levitra."
I'll refrain from making any of the bad jokes I'm thinking of at the moment.
Well, if you actually perform the search for "bev stayart levitra" you find that the association is made because most of top results are from her year old lawsuit with Yahoo. Well, they were, now they are from all the stories and blogs about this lawsuit AND her year old lawsuit.
Congratulations, Ms. Stayart, you are well on your way to permanently tying your name to both Yahoo and Levitra.
[edited title to be more informative by Bert]
Thursday, January 28, 2010
TOR cracked to catch child pornographers
Moore (arguably) had good reason to do this. In Germany, at least, TOR is being heavily used, or is suspected of being heavily used, to traffic in child pornography, and the German authorities have been cracking down on TOR servers. But is the possible benefit in one admittedly important area worth the cost in several other important areas?
But there is an alternative the the TOR package by itself. It is also cross platform, and free. It will run on Intel Macs, Windows, and Linux. It is called JanusVM and runs in a virtual machine. It plugs the holes used by Moore's patch, and keeps your location obscured. From the Janus website:
JanusVM is powered by VMware, built on the Linux 2.6.14 kernel, and brings together openVPN, Squid, Privoxy, and Tor, to give you a transparent layer of security and privacy that is compatible with all your TCP based applications. DNS request are also passed through Tor so even your ISP doesn't know what web site you are looking at.
JanusVM is free, cross platform, and can take a little more setup than the basic TOR package, depending on how your network is setup. But if you need anonymity online, it's the best thing going now.
Wednesday, January 27, 2010
A little more Facebook, good and bad
But it can be very bad, too. According to the Crime Scene KC blog, Micheal Cowley plead guilty to posing as a 17 year old girl in order to get naked pictures from teenage boys. This type of activity is unavoidable as long as Facebook doesn't do more ... More? Facebook doesn't do anything to verify who you are when you sign up. The surprise here isn't that someone posed as a teenager on Facebook to get naked pictures of other teens, it's that we don't hear of it more often. I would say I'm glad we don't, but I have to wonder how many just aren't getting caught. And it concerns me because I have teenagers and kids who are going to be teenagers in a few years. Do you know all of your kids Facebook friends?
Tuesday, January 26, 2010
TOR: Peeling the onion
Just as with any security system, there are things you need to be aware of, and the TOR download page lists some. One other gotcha that is mentioned somewhere on the website, but I can't find it at the moment, is the bandwidth and processing overhead required. Your web queries are being encrypted on the fly by your computer, and every query you send has have one level of encryption removed by each TOR server it goes through. That takes a little time, which means your queries take a little longer to reach the server you're sending them to. I'm using an older 1.33 GHz Powerbook, and TOR is useable, but the processor hit is noticeable. The bigger problem for me is the loss of javascript and Flash. You don't know how many sites you go to use those until you try to do without them.
But despite the imperfections, if your main goal is to obsure the origin of your web traffic, TOR is a useful tool. If you plan to just use it for browsing the web the default install bundles work great with Firefox. There are bundles for Windows, Mac and Linux, and they are preconfigured with additional software to make using TOR as easy as possible, even for people who aren't that technically inclined.
You can download a TOR bundle that pretty much sets you up for browsing with Firefox here (you have to install Firefox).
Check these pages on Wikipedia for more information on TOR and Onion Routing.
[Updated at 7:25 am for clarity by Bert]
[Updated at 11:45 am for clarity and spelling (Linux doesn't have an 's') by Bert]
Monday, January 25, 2010
Cost of music piracy: $2,250 per song.
The RIAA is a fear-mongering bully, and they need to be forcd to disband and allow artists to do their thing. The premise that internet sharing reduces CD sales is hogwash, and 70's folk singer Janis Ian makes a good case for the opposite here, and Eric Flint of the Baen Free Library makes a similar case here and amplifies on it here. Ian's article is also published in "Prime Palaver" on the Baen Free Library website. Both people can demonstrate that offering things free (including having your music pirated) leads to more - not less - sales.
It's inevitable the entrenched businesses with "strategies that work" will react violently to any new model that makes their way of doing business obsolete. But it's getting old. The iTunes music store has demonstrated quite well that legal online sales are not only feasable, but can be highly lucrative. But they still want to alienate their users by suing them. I'll never understand the corporate mind.
Sunday, January 24, 2010
What's coming up
Saturday, January 23, 2010
And the loser is...
The report is worth reading, if only for the top 20 list. Here's a sample:
#1 123456
I think that is the first thing tried after 'password' when trying to guess passwords
#20 QWERTY
And this is probably about #10 on the list of passwords to try when guessing.
Remember to use strong passwords. Imperva estimates that it would be possible for an attacker to crack 1000 RockYou accounts every 17 minutes. That would be all 32,000,000 accounts cracked in less than 2 weeks. Ok, not all accounts, because there were some strong passwords among them.
Strong passwords consist of at least 8 characters and are made of upper and lower case letters, numbers and special characters. Make all your passwords strong passwords.
Friday, January 22, 2010
PlainsCapital vs Hillary Machinery
tx_plow_boy asked what I though about "my bank" after the revelations by Hillary Machinery. Hillary is alleging that negligence on the part of PlainsCapital led to the theft of over $800,000 from Hillary Machinery's account. $600,000 was recovered, but Hillary Machinery wants PlainsCapital to admit that they are responsible and pay up.
I've read Walt Nett's article, "Company, bank blame each other," in the Avalanche-Journal. I've read what Hillary Machinery says in the news section on their website, and I've read the two stories about similar breaches they link to directly from their site. I'm going to take a closer look at the info we have on the Hillary Machinery breach and see what I can come up with. Most of the information I'm using will be straight from their website. As we look at this the circumstances of this theft, keep in mind that I am not a lawyer, and I have only the information I've read (and linked to for you) to go by.
Looking at the info provided by Hillary Machinery on their website, here is what we have. To shorten this a little, I'll take it point by point.
1. In November 2009 PlainsCapital became the target of cybercriminals. They used vulnerabilities in PlainsCapitals internet banking system and initiated fraudulent wire and automated clearinghouse transfers.
Since I can find no mention of similar data breaches at PlainsCapital, I would probably classify the bank as a victim. It appears that the target was actually Hillary Machinery. For the same reason, I would say that the bank was not where the vulnerabilities were exploited. The normal scenario when an institution gets breached is to grab as much information as possible, or in the case of banks, grab money in small amounts from as many accounts as possible. Grabbing a large amount of money from one account points to the exploited vulnerability being at Hillary Machinery.
2. Even though the transactions were not authorized by a representative of Hillary Machinery Inc and inconsistent with Hillary's the bank still allowed them to occur.
The "not authorized by a representative of Hillary Machinery" is a bit of a red herring. If the perp stole the needed information from Hillary Machinery, the bank woudln't know that it wasn't someone from Hillary until the transaction was set in motion, and even then maybe not until two or three had been made. At that point the bank should have contacted the company to make sure the transactions were legit.
3. To make matters worse, PlainsCapital Bank has yet to take responsibility for the stolen funds claiming that their Internet banking systems are "reasonably secure."
Face it. The bank can't admit any culpability. The second they admit any kind of fault they will be sued out of business. If this case ends the way these things usually do it will be settled out of court with PlainsCapital paying some undisclosed amount without admitting any fault.
I don't think the lions share of blame goes to PlainsCapital on this one. It looks like Hillary was breached, whether by a virus, a trojan, or social engineering. Any share of the blame that goes to PlainsCapital goes after Hillary recognizes their own part in this very expensive fiasco.
I hope that answers your question, tx_plow_boy.
Thursday, January 21, 2010
Microsoft, Champion of Privacy?
And there lies the rub. Microsoft is used to being the big dog on the block when it decides on a move. According the seoconsultants.com Bing is third in the search engine race. Google is first with over 70% of the search engine traffic. Yahoo is a very distant 2nd with a little under 15%, and Bing is relatively close behind Yahoo at a little under 10%. In other endeavors Microsoft can bring it's massive OS dominance to bear. In search that dominance is less helpful. If they can't give the results that Google or even Yahoo can, they won't dominate.
Search isn't the only area Microsoft is coming forth as a privacy champion. Cloud computing, which is an area Microsoft might be able to influence, is another area the Redmond giant is preparing to address. In her PCMag.com article, Microsoft Urges Cloud-Computing Privacy Bill, Chloe Albanesius reports that Microsoft's lead council, Brad Smith, lobbied (she said urged - sounds nicer) Congress for a modern privacy bill and unveiled a report that shows the vast majority of people are worried about their data in the cloud. In a keynote at the Brookings Institute in Washington D.C. he said:
"As we move to embrace the cloud, we should build on that success and preserve the personalization of technology by making sure privacy rights are preserved, data security is strengthened and an international understanding is developed about the governance of data when it crosses national borders."
He went on to say that the government needs to modify and pass laws to protect data and privacy as we move to cloud computing.
This all sounds very good. Microsoft may have realized that protecting data in the cloud is in it's own best interest. Crooks might go after my data, but they're more likely to go after Microsofts if we are both equally insecure. Only time will tell if Microsoft legitimately wants better privacy controls, or if they're preparing to exploit loopholes.
Wednesday, January 20, 2010
Facebook: More bad, a little good
The Bad
As if it weren't already dangerous enough to be on Facebook, Ellinor Mills writes in her column on CNET that researchers have found Facebook is vulnerable to click-jacking. In essence, click-jacking is putting an invisible layer over a legitimate web page. When a link on the legitimate page is clicked, the invisible layer hijacks the click and sends the person somewhere they didn't want to go. The same researchers also noted that Facebook allows third party apps to access user data without warning them. I've talked about this before - most recently in response to a comment yesterday. Facebook had a response to this problem:
"The only information apps can access without first showing the 'Allow' screen is publicly available information (the limited set of info that includes name, profile picture, gender, networks, friend list, and pages) and information set to be visible to everyone on the Internet," Facebook spokesman Simon Axten said.
The "limited set of info" seems overly broad. Does mafia war really need to know the networks I belong to and every friend I have on Facebook? And the default for all information on Facebook is now "set to be visible to everyone on the internet," so Facebook tells the apps I use everything I have on Facebook, unless I've changed the defaults. And they don't tell me they're doing it. It would be interesting to know how many people tighten their privacy on their Facebook accounts. I bet it's a pretty low percentage.
The Columbus Dispatch carried an article by Bridget Carey highlighting the many ways you risk identity theft by using Facebook. They range from viruses to fake friend requests. The problem is only made worse by the tendency to be more trusting on sites like Facebook.
The Good
The Tech Chronicles blog notes that Facebook is warning users about Haiti relief hoaxes. If you want to help Haiti through Facebook, go to the Facebook Global Disaster Relief Page.
A cnn.com story informs us that caller id spoofing company spoofem.com is going to be giving 2 super bowl tickets away to people who become fans of their Facebook page.
Well, that's the good and the bad today.
Tuesday, January 19, 2010
More Facebook woes...
PC World tells us: Job Seekers, Watch Your Walls -- Employers Check Facebook Among the other stats provided in the article: 53% of employers check social networking sites like Facebook when vetting potential employees and more plan to start. A lot of employers have let people go because of what's on their Facebook page, too.
From IndyPosted: AT&T Error Allowed Unauthorized Facebook Access. Apparently there is a problem with how cell phones connect to the internet - there is no indication of whether it's only on AT&T's network. The problem caused a family to be sent someone elses Facebook login info. [Update: According to CNET's Insecurity Complex column AT&T has fixed the problem.]
The Security Watch blog at PCMag.com asks the question, Is Facebook privacy a sham? And with good reason. Facebook supplies a public link for you to give to people who are not members. It allows people who are not members of Facebook to look at pictures that you have labeled "Me Only". Does no one at Facebook see the problem in this?
I don't hate Facebook. Social networks can be a great tool. I even have an account. But I am concerned that even the people who try to keep most of their info on Facebook private are doomed to expose far more than they intend because Facebook doesn't really allow users to keep anything private.
Monday, January 18, 2010
Lincoln National: Weak security, strong customer care
It will save a lot of time if we don't have to log out every time we leave a computer so other people log in if they need to...If we just make a few logins and share the information it'll save tons of time."
Of course, this goes against PCI and Sarbanes Oxley compliance because it ruins accountability. If more than one person uses a login it becomes almost impossible to prove who did what with it. Most companies I know check for shared logins (also known as generic logins) on at least a quarterly basis and get audited annually, so I'm not sure how this little snafu went on so long.
The company says that there is no evidence of improper use of the shared logins, but since there is no way to prove that no data was compromised Lincoln National is notifying state agencies and customers voluntarily and offering customers free credit monitoring.
It's nice to see a company that steps up to the plate and does the right thing when they screw up. I have a feeling there may still be an investigation and maybe some fines, but it won't hurt Lincoln National's case that they looked after their customers when a problem was discovered.
Sunday, January 17, 2010
Facebook gives McAfee away
If you already have security software and aren't having any problems I'd say don't worry about it. But be glad Facebook is showing signs of beginning ot understand that it is responsible for the well-being of it's users. I'm not real hopeful, but at least the appearances of concern are there.
Saturday, January 16, 2010
How's your Online Rep?
According to the article at Smart Planet, the first thing you need to do is find out what's out there about you. Just a few years ago the only people who really had to worry about their online rep were people who'd reached a certain status level in certain technical fields. Today almost any job you go to will check out your Facebook page and/or hit the search engines.
Have you googled your own name lately?
Some privacy advocates say googling yourself is a bad idea. Frankly, you can't afford not to google yourself - and Yahoo and Bing yourself (that last one just doesn't sound right, does it?). What you see is what potential employers are going to see, and each search engine give slightly different results.
Another blog entry at onlinereputationedge.com brings up a good, but seldom talked about point - what you say about other people online usually says a whole lot more about you than about the person you're talking about. So be careful what you say. And remember, once you put something online, it will never be gone, so the bad impression you create today could come back to haunt you thirty years from now.
Onlinerepmanagement.com uses Kanye West to teach us that even the biggest blunders - or group of blunders - can be mitigated by an active online presence. Because he is very active online you won't see much negative about him when you search for his name, even after 2009's gaffs. It's amazing what an active online presence can take care of.
That's it for now. Stay safe and work on that online rep.
Friday, January 15, 2010
Scans sans naughty-bits - maybe
Of course, spending millions of dollars on a technology that may not even address the problem it is supposed to solve is equally negligent. But I suppose I shouldn't be too surprised. We did it after 9/11 and we'll probably do it after the next successfull attack.
Thursday, January 14, 2010
Contactless card breach
It may not seem like a big deal, but its important to know how the switch happened. It's unlikely that the switch was caused by the cards. I've never liked RFID enhanced cards, be they ID's or credit cards. But this time I'm fairly certain the card is not the culprit. It is most likely either human error - which seems to be the official line - or a computer error. I'm sure the hope is that human error really is to blame. Then the solution is training or replacement. If it's computer error, it might not be fixable until the next system upgrade - and that could be bad news. System upgrades might be years down the road. Meanwhile, your metaphorical tail is left swingin in the breeze.
As we see more of these stories, will we come to realize that we would have been wiser to slow down and make sure things work the way we think they will before becoming very dependent on them for our wellbeing?
Wednesday, January 13, 2010
Eternal Ignorance
The original poster (OP) was looking for cheap software:
[caption id="attachment_640" align="alignnone" width="419" caption="Seeking deals in spam"]
[/caption]Everything about this deal screams "SCAM". Others agreed.
[caption id="attachment_643" align="alignnone" width="466" caption="Pointing out his error"]
[/caption]OP disagreed with everyone (there were many more, "Don't Do it!" posts.
[caption id="attachment_656" align="alignnone" width="432" caption="Does he really believe this?"]
[/caption]Did anyone actually read the first graphic? Do you remember him saying his VISA card was compromised in December, and he has no idea why.
I finally tried to explain why he was wrong. It didn't do any good.
[caption id="attachment_661" align="alignnone" width="600" caption="I weigh in"]
[/caption]The moderator killed the thread, but not before it was obvious that, no matter the risk, this guy was going to try to buy from spammers. Of course, part of the problem was his definition of spam. To him, any mention of a product in an electronic medium is spam. I know this because he used a thread about the Magic Jack internet phone service as an example of legitimate spam.
The rest of his problem was he didn't want to be educated. He asked for advice, then completely disregarded it. I'm sure one day he will be wondering how somebody found out enough about him to rack up hundreds of thousands of dollars worth of debt. Or maybe only tens of thousands. Either way, he could have gone a long way toward avoiding it by just not using spam to shop with.
Oh, and that link to check websites is: http://www.siteadvisor.com/
Enter the URL of the site you want to check in the box on the right:
[caption id="attachment_664" align="alignnone" width="600" caption="One useful tool"]
[/caption]Of course, if you are using current versions of most browsers, many have built in sitecheckers. But it's hard to overtest these things.
Hope this was helpful. Keep your eyes open and keep safe
Tuesday, January 12, 2010
Eternal Vigilance!
Once, years ago I almost fell for exactly this type of scam. I caught myself in time, but it was a near thing. Remember that if your credit card, bank, or anyone else who has enough information to pretend to be you ever calls asking for you to prove who you are, hang up and get the number off the back of your credit card or out of the phone book and call them. If they still say your information has been stolen, you can take the appropriate steps. But never give personally identifying information in direct response to a phone call, email, or mail.
Cartoon used with permission.
Monday, January 11, 2010
Airport romance never pays
But I watched the video of the his transgression (well, I watched the 6 minute unedited video), and it is obvious that he did know what he was doing was wrong. He waited around for several minutes, even after the guard asked him to move on. And I would think his girlfriend should be held responsible as well. She waited until the security guard was gone and came back for her boyfriend, then walked with him to the 'secure area.'
The guard is also culpable in this fiasco. He should not have left his post unattended. If he had some serious business he needed to attend to he should have called for relief.
How much trouble should they be in? I'm not sure. Unless he's been an exemplary employee for a long time, I would strongly recommend firing the guard. There is too much relying on his vigilance to let a slip like that slide. The lovebirds? I'm a little torn. I think they need more severe penalties than the crime he is being charged with carries (she isn't being held responsible, AFAIK), but I don't really want to ruin to lives over what might have gone entirely unnoticed a few short weeks ago.
That's the kicker, of course. And perhaps the damning bit that's missing. These two have been carrying on a long distance relationship for a year or so. How many times have they played exactly this scenario when she visits? Or when he visits? As I said earlier, he was obviously waiting, and it appears that she was, too. It looked like they had either done this many times, or planned it very carefully.
His reaction when he found out the police were at his house is also interesting. Almost like he was expecting it eventually. According to a story in the NY Daily News, he said, "You got me." It doesn't sound like there was any surprise at all. That just leaves the question, why is he the only one being charged?
Why does the girl go free when she went to get him - knowing he wasn't supposed to cross the secure barrier? The guard is facing disciplinary action, the boyfriend is being charged, however lightly, and the girlfriend walks. Doesn't sound right to me.
Sunday, January 10, 2010
Full body scans: Trading privacy for illusion of security?
In the past she has been against full body scanners and profiling in airports. Then she sat six seats in front of a young Nigerian man on Christmas day, 2009, and she remembers the sound of the detonator, the flash, and the terrorist being led down the aisle with no clothes on below the waste.
Her experience that day changed her view of how airport security should be handled. In an article in the Detroit Free Press she says: "I'm always standing up for rights and privacy concerns, but now I hope that body scans will be mandatory," Aref, 27, said Wednesday. "Balanced against national security, it's worth the invasion of privacy. And I acknowledge the fact that there has to be attention paid to Muslims."
Coming close to death is a life changing experience, but often after some time has passed and the fear moves further away people revert to their previous opinions and attitudes. Only time will tell us if Miss Aref will continue to favor body scanners and profiling. But her story, moving as it may be, is just another emotional appeal, and emotional appeals are poor things to build policy on. Granted emotional appeals are the stuff that shapes public opinion, but they're still bad for building policy.
One of the more interesting quotes on full body scanning and privacy came from an article in the Washington Post on January 4, 2009. It was about the images generated. It said,
"They're virtual. Passengers walk through the machines fully clothed; the resulting image appears on a monitor in a separate room and conceals passengers' faces and sensitive areas."
Correct me if I'm wrong, but I believe "sensitive areas" refers to the breasts and groin on women and the groin on men. If the groin area is concealed, how are we protected from an underwear bomb?
Here are a few other quotes from the same article:
"It covers up the dirty bits," said James Carafano, a homeland security expert at the conservative Heritage Foundation.
"I don't think it's any different than if you go to the beach and put on a bikini," said Brandon Macsata, who started the Association for Airline Passenger Rights.
"It covers up the dirty bits," and it's the same as a bikini ... that sounds to me like the primary area of concealment - the crotch, will be concealed by software in the scanner. That makes it kind of hard for the human viewing the image to see if anythings been added to the area.
I've read that the full body scanners are not designed to detect the types of explosives used in most terrorist attacks. According to an article at newsdaily.com, Dutch Interior Minister Guusje ter Horst said that there is no 100% gaurantee that the new detectors would have caught the underwear bomber.
Adding fuel to the fire - or not, since there's been almost no mention of it anywhere else, the Independent ran an article, Are planned airport scanners just a scam? on January 3rd reporting that British research into full body scanners showed that they would not detect an explosive of the type used by the crotchbomber. According the to article,
"But Ben Wallace, the Conservative MP, who was formerly involved in a project by a leading British defence research firm to develop the scanners for airport use, said trials had shown that such low-density materials went undetected.
Tests by scientists in the team at Qinetiq, which Mr Wallace advised before he became an MP in 2005, showed the millimetre-wave scanners picked up shrapnel and heavy wax and metal, but plastic, chemicals and liquids were missed. "
Other interesting claims are made. Supposedly American experts have stated that traditional airport pat downs wouldn't have stopped Mr. Abdulmutallab from getting on the plane. There's a really simple reason for it. In the U.S. the security people aren't allowed to frisk sensitive areas. Not that frisking those areas will stop everyone. I was with a friend going into "The Who's Last" concert in Dallas in 1983...I think that was the concert...anyway, they were frisking everyone. My friend had a recorder with the mike in his pants. The officer hit the mike,
"What's that!"
"My d**k."
The officer got a surprised look on his face and waved him through. I still wonder if anyone managed to get something more dangerous in that way?
For me the scanner issue isn't really about privacy, although that is important. It's really about using unproven technology without making sure the measures we already have in place are working. To be honest they usually do work, but we need a lot of improvement. And before we spend $165 million on scanners we should spend a few hundred thousand making sure they do what is claimed.
Does anyone remember the bomb sniffing machines they spent millions on after 911? The machines that are mostly decommissioned because they didn't work as claimed, and spent more time broken than working? We don't want that to happen again - but it's probably already to late, because they've already ordered them. And they may not even detect the explosive they're being bought to protect us from.
The more things change the more they stay the same.
[Edited at 12:21 to improve headline by Bert]
Saturday, January 9, 2010
Well, Duh...
Don't get me wrong, the headline is accurate, but to anyone who's been watching these things, and I suspect many who haven't, that's kind of like saying fire is hot. Apparently 1 in 6 people in Massachusetts have been victim of identity theft, and that is what brought this problem to their attention.
1 in 6 people. With the number and scope of data breaches that have happened just in the last two years it's a little surprising it's not 1 in 4 or even 1 in 3. I know 2 people whose identities may have been compromised, and 1 whose identity was most definitely stolen. Identity theft is a big problem, I'm just surprised it took Credit.com this long to realize it.
Friday, January 8, 2010
Obama shoulders responsibility
Thursday, January 7, 2010
Bono's hurting because of music pirates?
There are a few things he is ignoring, however. There is a thriving indy music industry based on internet distribution. Many young artists have started their careers using the internet and are quite happy as regional sensations. Other types of content providers have discovered that carefully managed free distribution increases sales instead of decreasing them. Baen books started an experiment in 1999 or 2000. Instead of trying to stop internet sharing, they embraced it. They put some of the older titles of authors who were willing to give away a book or two online as free downloads. They're still doing it today. I'll give you three guesses why.
If you are a fan of fantasy and science fiction, check out the Baen Free Library. And see how intelligence and forward thinking handle new "problems". And after picking up a book or two by an author you've never read before, if you like it, buy something else by the same author. After all, he was nice enough to give you an enjoyable free read, and he's got bills the same as you and I.
Wednesday, January 6, 2010
Facebook Frightened?
Another service, Power.com, allows you to access many social networking sites from one, making social networking easier. Again, Facebook is taking legal action. I can understand this one. Facebook makes money from ads. No visits to your Facebook page, no ads displayed or clicked, no money.
Last, we have Suicide Machine, a service which will completely remove you from Facebook. You cannot simply log back in, you will have to create a whole new Facebook profile after using Suicide Machine. Facebook is blocking the Suicide Machine IP, so right now the service isn't available.
The amusing (sic) thing about Facebooks reaction to these services is that they claim to be doing it out of concern for users privacy. They obviously think being concerned with privacy = being soft in the head. How can my choosing to use one of these services be more hazardous to my privacy than Facebook making the default "privacy" setting for everything "Share with the world"?
Double standards. Gotta luv 'em.
Monday, January 4, 2010
Full body scan - shield or show?
Privacy groups are against the full body scanners, saying they are invasive and demeaning. Flyersrights.org and the ACLU are both against the scanners. In a release on its website the ACLU says:
"We should be focusing on evidence-based, targeted and narrowly tailored investigations based on individualized suspicion, which would be both more consistent with our values and more effective than diverting resources to a system of mass suspicion," said Michael German, national security policy counsel with the ACLU Washington Legislative Office and a former FBI agent. "Overbroad policies such as racial profiling and invasive body scanning for all travelers not only violate our rights and values, they also waste valuable resources and divert attention from real threats."
I have to admit, I lean more toward the ACLU position. Yes, I know that a full body scan might have caught the explosive in the bombers undies - although there are claims that the bomb would have made it through a scanner. But that isn't really the issue. The issue is that we don't need to add any new security measures, we need to properly use the ones we have.
I can't say it enough. The system is broken. People are saying, "We need full body scans to keep anyone else from getting through." No, we need to start making full use of the intel we're gathering. Bush dropped the ball when he didn't follow through on his order that the U. S. intelligence agencies, FBI, CIA, NSA, etc. share information, and Obama is following his example.
The point in this is not that a scanner would have stopped this guy before he could turn himself into a eunich. It is that he should never have made it to the point where he would have to go through a scanner. We had more than enough info to forbid this guy to get on a plane. He was on a watch list, then his father notified the U.S. Embassy that he had been radicalized and might do something dangerous. That would have put him in a "watch very closely" list for me. Not for the U.S. government. According to examiner.com:
"On November 20th the embassy sent a "Visas Viper cable" to the State Department which detailed the father's warning. The information was then given to the Counter-Terrorism Center in Washington D.C. which ruled that their was insufficient information present to revoke Mutallab's visa."
While people are screaming for more measures to limit our freedoms and take away our rights, the real problem is that the information we are gathering has everything we need to stop these terrorists, if we would only use it. Putting scanners in the mix will not make us safer, it will only be one more layer of false security.
No matter what methods we devise to detect explosives at the airport, our first and best line of defense will always be gathering data to stop terrorists before they can get a ticket. And the evidence shows we're doing a good job of gathering it, we just aren't using what we're getting.
Sunday, January 3, 2010
Rockyou sue
I suppose it's not too surprising that the RockYou data breach is ranked as one of the top 5 (or should that be bottom5?) data breaches of 2009 by PCWorld, but the sad thing is that in today's day and age they should have been the worst. PCWorld didn't actually rank the top 5, just picked the worst 5 and listing them. But several qualify as worse, either for the number of people affected or the length of time it took to report the breach. One company took six months to notify anyone of a data breach. As long as companjies try to stall like that, notification laws will be needed.
Saturday, January 2, 2010
What is cloud computing?
That seems pretty harmless. But protecting email is one thing. Protecting major financial, medical, or other sensitive data is quite another. And we have problems protecting the email. There are ways of analyzing memory usage to steal data when two programs are running on the same computer and operating system. Theoretically it should work for two virtual computers running on the same server, but with dozens or hundreds of them running on a server, it was believed that actually isolating useful data that way was very unlikely.
Technology Review ran a story on cloud security called "Security in the Ether". One of the first things it talked about was three researchers who had shown that it is possible to monitor virtual machines the same way. They did their research on Amazon's cloud servers, but Amazon says they have taken steps to make sure that data can't be stolen by that method anymore.
But that isn't the only concern about cloud computing. There are concerns over downtime, application security, data security, the human factor. Perhaps you've heard that the more people who know a secret, the less likely it is to remain secret? There's a cloud computing corollary. The more people in the cloud, the more likely there will be a breach. And cloud computing is only economical if lots of people are using it.
Friday, January 1, 2010
"The Cloud" is easy to fall through
In the NY Times "Bits" blog, Nick Bilton asks if your data is safe in the cloud. And with good reason. He's just read an article by David Talbot that examines what types of problems exist in cloud security. He finds two researchers whose work shows that it isn't all that difficult to gather data from the cloud. The article goes on to ask a lot more questions, but the gist is that data in the cloud can be very easy to access. The risks are high, and that data will be compromised is almost certain. Before we leap willy-nilly into this thing called cloud computing, it would be a good idea to understand it a lot better, and work on it's drawbacks. But it doesn't look like that's on anyone's agenda, and some things are going to have to go radically wrong before it gets put there.
Tomorrow I'll be looking at what exactly cloud computing and how it works - and how that effects your data in the cloud.
The obligatory New Years Prediction
Does this mean that our state governments are trusting Google with sensitive information? Not necessarily. In fact, probably not. But it does mean that there is a lot of information being entrusted to Google that wasn't just a few months ago. And there is no way to ensure that sensitive data won't be sent through Googles servers, and that brings us to my prediction: This year there will be a data breach of unrivaled severity, and it will be through Googles cloud computing services. It will massively slow down the adoption of SAAS (software as a service) as companies and individuals realize the security models we have today are not suited to the cloud. It will strengthen Microsofts position (supposedly threatened by Google Docs) in the enterprise as organizations trip over each other to get away from Google Docs and back to Microsoft.
Such a breach could be a good thing in the long run if it makes us look at cloud computing and reexamine our security paradigms in light of the new and unique requirements of protecting data in the cloud. But depending on what is breached, in the short term it could be very ugly.